Stored Cross-Site Scripting Vulnerability in Pixelimity by Pixelimity
CVE-2022-28589

4.8MEDIUM

Key Information:

Vendor

Pixelimity

Vendor
CVE Published:
3 May 2022

What is CVE-2022-28589?

A stored cross-site scripting (XSS) vulnerability exists in Pixelimity version 1.0, which can be exploited by attackers to inject and execute arbitrary web scripts or HTML code. This can occur via the Title field in the admin interface, particularly when adding new pages. Successful exploitation allows unauthorized control over web pages, posing a significant security risk to affected users.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.